
GIAC Cloud Threat Detection
Domain 2Objective 4
Application and Proxy Monitoring GCTD Practice Questions (Page 6)
Part of the Cloud Infrastructure Monitoring domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 26–30
- 26
A company's web application is experiencing a distributed denial-of-service (DDoS) attack. The attack is characterized by a high volume of requests to a single endpoint, each with a different source IP. The team has access to both application and proxy logs. What is the most effective way to differentiate between legitimate traffic and the attack?
Select an answer first - 27
What is a typical first response step after an alert is triggered for a potential application or proxy threat?
Select an answer first - 28
A security team is implementing a forward proxy to monitor outbound traffic from a cloud environment. They need to ensure that all traffic from virtual machines is inspected, including traffic that uses non-standard ports. What is the most important configuration step?
Select an answer first - 29
What is a key component of an alerting strategy for threats detected through application and proxy monitoring?
Select an answer first - 30
What is the primary purpose of application monitoring in the context of cloud threat detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.